On September 1, independent journalist Brian Krebs discovered a dark web site named Nexus selling digital scans of tens of millions of driver’s licenses from the US and Canada, along with millions of other ID and travel documents and hundreds of thousands of medical records [1, 2, 3, 4, 5, 6, 7]. Krebs verified the authenticity of the stolen data by contacting nine individuals whose licenses appeared on the site [1, 3, 4, 5, 6, 7].

The Nexus site advertised itself on a Russian cybercrime forum and claimed to add around 500,000 new documents daily, indicating an active and ongoing breach [1, 2, 4, 5, 6, 7]. Cybersecurity researcher Zach Edwards said, “There’s never been a breach of driver’s licences at this scale,” and warned the breach created "legitimate national security risks for high-profile individuals" [1]. He repeated the point in Mandarin, saying “從未發生過如此大規模的駕照外洩事件” and “這次攻擊對知名人士構成了切實的國安風險” [6].

Krebs and Edwards identified IDScan.net, an identity verification provider based in New Orleans, as the likely source of the compromised data [1, 2, 4, 5, 6, 7]. IDScan.net is investigating but has not responded to media inquiries [1, 2, 4, 5, 6, 7]. The FBI’s New Orleans field office is specifically involved in the investigation [2].

The Nexus site disappeared from the internet shortly after Krebs’ report on September 1 [1, 2, 3, 4, 5, 6, 7]. The FBI announced on September 2 that it is investigating the breach but declined further comment due to the ongoing nature of the inquiry [1, 3, 4, 5, 6, 7].

The stolen data puts tens of millions of people at risk of identity theft and fraud, affecting residents of the US and Canada [1, 4, 5, 6, 7]. Authorities and cybersecurity experts are continuing to probe the breach. The FBI investigation remains active with few details released so far [1, 3, 4, 5, 6, 7].